vendor:
AcySMS
by:
Sureshbabu Narvaneni
8.8
CVSS
HIGH
CSV Injection
897
CWE
Product Name: AcySMS
Affected Version From: 3.5.0
Affected Version To: 3.5.1
Patch Exists: YES
Related CWE: CVE-2018-9106
CPE: a:acyba:acysms
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 14.04 x86_64/Kali Linux 4.12 i686
2018
Joomla! Component AcySMS 3.5.0 CSV Macro Injection
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extension before 3.5.1 for Joomla! via a value that is mishandled in a CSV export. Login as low privileged user who is having access to AcySMS Component. Rename user name as @SUM(1+1)*cmd|' /C calc'!A0. When high privileged user logged in and exported user data then the CSV Formula gets executed and calculator will get popped in his machine.
Mitigation:
Upgrade to version 3.5.1